ZuckerBot — Meta Ads MCP Server
NPM · ZUCKERBOT-MCP · 2 COMPONENTS · SCANNED AUG 3
60+ Meta Ads tools for AI agents: audits, campaign management, audiences and CAPI tracking.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →
Supply Chain Security83
- No malware found by supply-chain analysis.Pass
- CVE check failed: a known medium-severity CVE affects @hono/node-server 1.19.17, reached via @modelcontextprotocol/sdk > @hono/node-server. A fixed version is available. View diagnostics → Fail
- No install/post-install scripts declared.Pass
- Only part of the dependency tree could be resolved (113 of 117), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency45
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 7 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability56
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 9145 tokens (~152/item across 60 items; 60 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
npm · zuckerbot-mcp
claude mcp add crumbedsausage-zuckerbot -- npx -y zuckerbot-mcp
codex mcp add crumbedsausage-zuckerbot -- npx -y zuckerbot-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"crumbedsausage-zuckerbot": {
"type": "local",
"command": [
"npx",
"-y",
"zuckerbot-mcp"
],
"enabled": true
}
}
} openclaw mcp add crumbedsausage-zuckerbot --command npx --arg -y --arg zuckerbot-mcp
mcp_servers:
crumbedsausage-zuckerbot:
command: "npx"
args: ["-y", "zuckerbot-mcp"] {
"mcpServers": {
"crumbedsausage-zuckerbot": {
"command": "npx",
"args": [
"-y",
"zuckerbot-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 −3
No change was recorded against any check on this day. Supply Chain Security went from 93 to 83. Other categories moved too: Stability & Change Management rose 4.
- 2 Aug 26 +25
- Known CVEs: unverified → fail ▼ security
- Malware scan: unverified → pass ▲ security
- Dependency health: unverified → partial ▲ functional
- 1 Aug 26 −9
- Known CVEs: fail → unverified ▼ security
- Dependency health: partial → unverified ▼ functional
- 31 Jul 26 +45
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 −40
- Provenance: fail → unverified ▼ security
- Known CVEs: fail → unverified ▼ security
- Install scripts: pass → unverified ▼ security
- GHSA-frvp-7c67-39w9 no longer affects this package ▲ security
- Dependency health: partial → unverified ▼ functional
- Maintenance: pass → unverified ▼ functional
- Security disclosure: fail → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- License: pass → unverified ▼ functional
- Licence: MIT functional
- 29 Jul 26 +20
- GHSA-frvp-7c67-39w9 affects this package: medium ▼ security
- Known CVEs: unverified → fail ▼ security
- Provenance: unverified → fail ▼ security
- Install scripts: unverified → pass ▲ security
- License: unverified → pass ▲ functional
- Dependency health: unverified → partial ▲ functional
- Maintenance: unverified → pass ▲ functional
- Licence: MIT functional
- 28 Jul 26 +20
- Tool coverage: unverified → 100 ▲ functional
- First check of Schema quality: fail functional
- First check of Tool coverage: 100 functional
- First check of Schema quality: fail functional
- First check of Schema quality: unverified functional
- 27 Jul 26 6
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Analysed npm/[email protected]
Provenance none
Ecosystem: npm · Outcome: none
Vulnerabilities 1 finding
| ID | CVE | Severity | Vector | Fix available |
|---|---|---|---|---|
| GHSA-frvp-7c67-39w9 | medium | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N | yes |
Dependencies 113 packages
113 packages in the resolved dependency tree · 112 deprecated · 34 stale.
The dependency tree was only partially resolved, so these counts may be incomplete.
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
zuckerbot_research_reviews ~126
Fetch review intelligence for a business by name. Searches Google and Yelp to surface star rating, review count, recurring sentiment themes, and standout customer quotes that can be used directly in ad copy. Use before creating a campaign to identify proof points and objection-handling angles.
| Name | Type | Req | Description |
|---|---|---|---|
| business_name | string | yes | Business name to research reviews for (e.g., 'Rosebud Dental Austin') |
| location | string | — | Optional city/region to narrow review search (e.g., 'Austin, TX') |
| platform | string | — | Review platform to search. Defaults to all. |
No output schema declared.
No examples provided.
zuckerbot_rotate_webhook_secret ~101
Rotate the Conversions API webhook secret for a business. The new secret is returned exactly once, in this response only — every other read shows just webhook_secret_set and webhook_secret_last4. The old secret stops authenticating immediately, so update the system that signs your inbound webhooks (for example your CRM workflow's stored secret) in the same sitting.
| Name | Type | Req | Description |
|---|---|---|---|
| business_id | string | — | Optional business ID override for the authenticated API key |
No output schema declared.
No examples provided.
zuckerbot_send_capi_event ~365
Manually send a Conversions API event for a business contact/lead. Useful for debugging CAPI pipelines, testing stage mappings with real user data, or sending events from custom integrations not covered by the webhook. Authenticates with the business API key OR with an x-zuckerbot-webhook-secret header if using the webhook path.
| Name | Type | Req | Description |
|---|---|---|---|
| business_id | string | — | Optional business ID override (resolved from API key when omitted) |
| crm_source | string | — | Optional CRM source label override (e.g., 'hubspot', 'salesforce') |
| string | — | Optional contact email for identity matching | |
| event_time | string | — | Optional ISO 8601 event timestamp. Defaults to now. |
| fbc | string | — | Optional pre-formatted Facebook click cookie (fb.1.<ms>.<fbclid>), forwarded raw — never hashed |
| fbclid | string | — | Optional Facebook click ID; the server builds a well-formed fbc cookie from it |
| fbp | string | — | Optional Facebook browser ID cookie (_fbp), forwarded raw — never hashed. Improves match quality for every event |
| first_name | string | — | Optional first name for identity matching |
| last_name | string | — | Optional last name for identity matching |
| lead_id | string | — | Optional ZuckerBot lead ID for attribution matching |
| meta_lead_id | string | — | Optional Meta Lead Gen Ads lead ID for attribution matching |
| phone | string | — | Optional contact phone for identity matching |
| source_stage | string | yes | CRM stage key to map to a Meta event (e.g., 'lead', 'salesqualifiedlead', 'customer') |
| value | number | — | Optional event value override in major currency units |
No output schema declared.
No examples provided.
zuckerbot_set_capi_config ~297
Update the Conversions API configuration for a business. Set stage-to-event mappings (e.g., 'lead' → Meta Lead event), enable/disable delivery, change the CRM source, currency, optimisation target, or action source. Changes take effect immediately for new CAPI events. Use zuckerbot_capi_test to verify the updated config works.
| Name | Type | Req | Description |
|---|---|---|---|
| action_source | string | — | Meta Conversions API action_source. Defaults to website for CRM events |
| business_id | string | — | Optional business ID override for the authenticated API key |
| crm_source | string | — | CRM source label, such as hubspot |
| currency | string | — | Business currency used for CAPI event values, such as USD or AUD |
| event_mapping | object | — | CRM stage mapping object keyed by source stage. Stage keys are normalised (lower-cased, non-alphanumerics stripped: signup_completed → signupcompleted); inbound webhook source_stage values are normal… |
| is_enabled | boolean | — | Enable or disable CAPI delivery for the business |
| optimise_for | string | — | Downstream optimisation target for autonomous evaluation |
| rotate_webhook_secret | boolean | — | Rotate the webhook secret on update. The new secret is returned exactly once in the response; prefer zuckerbot_rotate_webhook_secret for a dedicated rotation |
No output schema declared.
No examples provided.
zuckerbot_suggest_angles ~65
Return only the creative angles and audience tiers for a campaign draft — a lightweight alternative to zuckerbot_get_campaign when you need just the strategy summary without the full campaign payload, stored creatives, or tier execution details.
| Name | Type | Req | Description |
|---|---|---|---|
| campaign_id | string | yes | Campaign ID |
No output schema declared.
No examples provided.
zuckerbot_sync_conversion ~238
Send downstream conversion quality feedback to Meta via CAPI. When a ZuckerBot-sourced lead converts (sale, appointment, qualified call) or bounces (uncontactable, bad fit), reporting it here teaches Meta's algorithm to find more (or fewer) people like them — improving lead quality over time. Call this from your CRM when a lead status changes.
| Name | Type | Req | Description |
|---|---|---|---|
| campaign_id | string | yes | ZuckerBot campaign ID |
| fbc | string | — | Optional pre-formatted fbc cookie, forwarded raw — never hashed |
| fbclid | string | — | Optional Facebook click ID; the server builds a well-formed fbc cookie from it |
| fbp | string | — | Optional _fbp browser cookie, forwarded raw — never hashed. Improves match quality |
| lead_id | string | yes | Lead ID to report conversion for |
| meta_access_token | string | yes | User's Meta access token for CAPI |
| quality | string | yes | Lead quality: 'good' = converted/contacted, 'bad' = lost/unresponsive |
| user_data | object | — | Optional user data to improve match rate |
No output schema declared.
No examples provided.
zuckerbot_tag_creative ~114
Tag Meta ads with creative attributes (hook type, visual style, product focus, CTA type, copy tone, setting) by providing ad metadata and optional asset URLs. ZuckerBot uses Claude vision to analyze the creative and store structured tags. These tags feed the zuckerbot_creative_analysis pipeline. Run this after launching new ads to keep the creative intelligence database current.
| Name | Type | Req | Description |
|---|---|---|---|
| ads | array | yes | One or more Meta ads to tag with creative attributes |
| business_id | string | — | Optional business ID override |
No output schema declared.
No examples provided.
zuckerbot_update_portfolio ~136
Update the name, total daily budget, active status, or tier configuration of an existing audience portfolio. Changes to budget and tiers take effect on the next autonomous evaluation cycle. Use this to adjust a portfolio without relaunching all tiers.
| Name | Type | Req | Description |
|---|---|---|---|
| is_active | boolean | — | Enable or disable the portfolio for autonomous evaluation |
| name | string | — | New portfolio name |
| portfolio_id | string | yes | Audience portfolio ID to update |
| tiers | array | — | Updated tier configuration. Replaces the existing tiers array. |
| total_daily_budget_cents | integer | — | New total daily budget in cents (minimum 500) |
No output schema declared.
No examples provided.
zuckerbot_upload_business_context ~125
Upload a text document (ad performance data, brand guidelines, customer data, sales data, or competitor analysis) so ZuckerBot can extract structured planning insights from it. Accepts raw text content — not binary files. Use this when the business has existing performance data or brand docs that should inform campaign strategy.
| Name | Type | Req | Description |
|---|---|---|---|
| business_id | string | — | Optional business ID override |
| content | string | yes | File content as text |
| context_type | string | — | Optional hint about the type of uploaded context |
| filename | string | yes | Name of the file or document |
No output schema declared.
No examples provided.
zuckerbot_upload_creative ~139
Upload finished creative assets (images or videos) to an approved intelligence campaign. ZuckerBot queues the Meta upload and ad-creation jobs asynchronously, then polls until they complete or the polling window expires. Use this when you have your own creative assets ready.
| Name | Type | Req | Description |
|---|---|---|---|
| campaign_id | string | yes | Intelligence campaign ID |
| creatives | array | yes | Creative assets to attach to the campaign |
| meta_access_token | string | — | Optional Meta/Facebook access token override |
| meta_ad_account_id | string | — | Optional Meta ad account ID override (format: act_XXXXX) |
| meta_page_id | string | — | Optional Facebook Page ID override |
No output schema declared.
No examples provided.